Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2011/12/25/9 | third party advisory mailing list |
https://developer.joomla.org/security/news/303-20090723-core-com-mailto-timeout-issue.html | vendor advisory |